<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Italian Conference on Cybersecurity, April</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Priorities on Vulnerabilities afecting Healthcare Organizations</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Gustavo Gonzalez-Granadillo</string-name>
          <email>gustavo.gonzalez@atos.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Rodrigo Diaz</string-name>
          <email>rodrigo.diaz@atos.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Eleni Veroni</string-name>
          <email>veroni@unipi.gr</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Christos Xenakis</string-name>
          <email>xenakis@unipi.gr</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="editor">
          <string-name>Vulnerability Discovery Manager, Vulnerability Assessment, Multi-factor Mechanism, Priority Assign-</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Atos Research &amp; Innovation, Cybersecurity Unit</institution>
          ,
          <country country="ES">Spain</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Piraeus, Department of Digital Systems</institution>
          ,
          <country country="GR">Greece</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>ment</institution>
          ,
          <addr-line>Healthcare Organizations</addr-line>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2021</year>
      </pub-date>
      <volume>0</volume>
      <fpage>7</fpage>
      <lpage>09</lpage>
      <abstract>
        <p>A key aspect on any risk assessment process is the identification and analysis of vulnerabilities associated to the target organization, its assets, services and devices. Considering that not all vulnerabilities are equally dangerous, and organizations cannot aford to blindly define strategies against the hundreds of newly discovered vulnerabilities, they must define priorities during the vulnerability management process. In addition, while many organizations base their prioritization of vulnerability management on scores such as the Common Vulnerability Scoring System (CVSS), a high portion of vulnerabilities associated to malware are scored with low or medium severity on the CVSS scale, which suggest that focusing only on CVEs which score high or critical would be a mistake. We propose in this paper a multifactor assessment mechanism to define priorities of vulnerabilities afecting Healthcare Organizations. The mechanism helps classifying vulnerabilities based on their score and assigning priorities for their treatment.</p>
      </abstract>
      <kwd-group>
        <kwd>Healthcare</kwd>
        <kwd>https</kwd>
        <kwd>//ggranadillo</kwd>
        <kwd>wixsite</kwd>
        <kwd>com/english (G</kwd>
        <kwd>Gonzalez-Granadillo)</kwd>
        <kwd>https</kwd>
        <kwd>//booklet</kwd>
        <kwd>atosresearch</kwd>
        <kwd>eu/rodrigo-diaz</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>With the discovery of new types of cyber-attacks and digital healthcare platforms being
universally recognized as Critical Infrastructures, healthcare organizations realize the need to
be technologically prepared against such challenges. Hospitals and healthcare centers have
started taking actions to protect themselves inside the current landscape of attacks but most
importantly to be able to react and mitigate new and unknown threats.</p>
      <p>
        The health sector is exposed to a great number of threats that exploit vulnerabilities that
in some cases are unknown by the target infrastructures. According to a recent report [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ],
vulnerabilities in healthcare IT infrastructure increased 341 percent between 2017 and 2018. In
nEvelop-O
LGOBE
(C. Xenakis)
addition, cyber attacks in the healthcare domain compromise not only network devices and
data, but also applications and services supporting critical patient care systems. In this sense,
healthcare centers must adopt new procedures to strengthen their systems and raise awareness
among their employees .
      </p>
      <p>
        One of the key phases in a vulnerability management process is the vulnerability analysis
that aims to prioritize the risks to which organizations are exposed if a given vulnerability
is successfully exploited. Considering that not all vulnerabilities are equally dangerous, and
organizations cannot aford to blindly define strategies against the hundreds of newly discovered
vulnerabilities, they must define priorities during the vulnerability management process.
Prioritization is therefore, the key to a successful implementation of new vulnerability management
programs [
        <xref ref-type="bibr" rid="ref2 ref3">2, 3</xref>
        ].
      </p>
      <p>
        While many organizations base their prioritization of vulnerability management on scores
such as the Common Vulnerability Scoring System (CVSS) [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], a high portion of vulnerabilities
associated to malware are scored with low or medium severity on the CVSS scale, which suggest
that focusing only on CVEs which score high or critical would be a mistake [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. It is therefore
important to develop new mechanisms of computing a vulnerability assessment based on
multiple factors.
      </p>
      <p>We propose a multi-factor assessment mechanism to define priorities of vulnerabilities
affecting Healthcare Organizations. The mechanism is performed by a Vulnerability Discovery
Manager (VDM) tool and will cover both cybersecurity and privacy vulnerabilities with a
particular focus on health data, healthcare information systems and medical devices. The proposed
approach is expected to help in the classification and prioritization of security vulnerabilities.</p>
      <p>The remainder of this paper is organized as follows: Section 2 provides an overview of
the vulnerability challenges identified in healthcare environments. Section 3 presents the
Vulnerability Discovery Manager reference architecture by detailing its main components.
Section 4 introduces the proposed multi-factor vulnerability assessment mechanism. Section 5
provides a use case example to show the applicability of the proposed mechanism. Section 6
provides related works. Finally, conclusions and perspectives for future work are provided in
Section 7.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Vulnerability Challenges in the Healthcare Context</title>
      <p>
        Much like any other domain where new technologies have emerged, healthcare faces
increasingly more and more challenges to its cybersecurity. According to a recent study by Bugcrowd
[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], between 2017 and 2018, the number of vulnerability submissions increased more than three
times compared from previous years, from which around 30% had a critical severity. Healthcare
organizations face most of their threats against their web site applications, with an average of
75% of the cases. This is mostly due to the fact that the medical practitioners as well as the
manufacturers and developers providing said technologies do not often prioritize security. This,
however, can be proven critical both to the health organization they work for and of course, to
the patients’ health and fundamental rights.
      </p>
      <p>With no standards, guidelines and good practices communicated to all parties involved, and
no known published examples of incidents in the industry until recently, as well as undisclosed
details of such incidents where other vulnerabilities do not become known to the public or the
industry, there is no standard way of making and using medical equipment handling data that
will ensure security throughout its lifecycle. This leads to existing yet unknown vulnerabilities
being either exposed, posing a threat to the reputation of the manufacturer and the provider, or
worse, exploited, in which case personal and sensitive data can be compromised along with the
smooth continuity of healthcare services provided. This can have critical consequences, such as
major financial loss or even the loss of human life.</p>
      <p>Additionally, until recently, a possibly false sense of safety was the norm in the healthcare
industry, because it did not seem as a possible target for cyber-attacks. However, this changed
ever since the medical records became electronic and are now stored and distributed online. The
introduction of Electronic Medical Records (EMR) and Personal Medical Records (PMR), as well
as the utilization of cloud services and storage, created a new attack surface for malicious parties.
The value of such sensitive data, particularly on platforms where they would be exploited for
identity theft or ransom, in combination with the lack of robustness of the security mechanisms
of the healthcare infrastructures, pose an attractive target for attackers.</p>
      <p>
        As no standard procedures have been established yet, the measures taken proactively by
providers in order to protect their assets, may not be as efective. It has been observed that there
are still healthcare organizations that have not created a cyber insurance policy taking into
account security controls, nor have put their staf through cyber hygiene training, in fear that
adding more security mechanisms to the system would interfere with their work. To overcome
this, clear and strict procedures need to be established for all stakeholders who are part of the
healthcare domain [
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref7 ref8 ref9">7, 8, 9, 10, 11, 12</xref>
        ].
      </p>
      <p>Vulnerabilities in the Healthcare domain, originate due to a multiple number of causes [13]:
(i) Most healthcare services and devices require single-factor authentication, making them a
potential target to many threats (e.g., brute-force attacks); (ii) Some healthcare devices and apps
share patient data with no data protection mechanisms, making them more vulnerable to attacks
like Man-in-the-Middle (MITM); (iii) Errors and/or intentional incidents caused by insiders
constitute one of the most common threat vectors in Healthcare organizations; (iv) Medical
device security practices in place (e.g., code review, debugging systems and dynamic application
security testing) lack of quality assurance and testing procedures [14]; (v) Disconnection between
the perceptions of medical device manufacturers and healthcare practitioners about security
implications of the medical equipment used; (vi) An important number of vendors and users do
not disclose cybersecurity and privacy issues afecting their IoT medical devices, which block
communications of vulnerabilities and threats in due time among healthcare organizations; (vii)
Some medical devices run with outdated software and operating system.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Vulnerability Discovery Manager (VDM)</title>
      <p>The Vulnerability Discovery Manager (VDM) is a domain-specific tool that identifies, analyses
and manages vulnerabilities in the target infrastructure. VDM has been designed to support
the key needs of the e-health sector (e.g., criticality and availability) aiming to: (i) identify
vulnerabilities to system resources (discovery); (ii) classify and assign priorities to detected
vulnerabilities (assessment); (iii) define remediation solutions to mitigate detected vulnerabilities
(treatment); and (iv) provide intelligence sharing functionality in order to share the information
with other hospitals and healthcare providers (sharing). In this paper we will focus on the
assessment capabilities of the tool.</p>
      <p>The VDM needs as input data the identification of the assets composing the target
infrastructure. The discovery of the assets can be performed using any network scanner such as
Nmap or a similar tool. The idea is to obtain information about the network and system devices
(e.g., workstations, servers, printers, smartphones, etc.) to start the process of discovering
vulnerabilities. Each device is identified by a unique IP address in the system, therefore having
a list of IP addresses for all the elements (e.g., nodes, assets) composing the monitored system
will trigger the analysis performed by the VDM.</p>
      <p>As depicted in Figure 1 VDM has four main components: (i) vulnerability scanner, (ii)
vulnerability storage, (iii) vulnerability assessment, and (iv) vulnerability reporting and sharing.
The remainder of this section details each VDM component.</p>
      <sec id="sec-3-1">
        <title>3.1. Vulnerability Scanner</title>
        <p>This module is in charge of discovering and associating vulnerabilities to the list of nodes
present in the input file. It is composed of two main processes: (i) vulnerability identification;
and (ii) asset tagging and management. After the identification of vulnerabilities, the tool will
associate each node/asset with its corresponding vulnerabilities. This process allows to verify
that vulnerabilities match the assets (e.g., devices, equipment, software) in the target network.
The objective of this process is to reduce the number of false positives or negatives and to
concentrate on the system’s exploitable weaknesses. The outcome of this process is a list of
assets and associated vulnerabilities that will be stored in the VDM database and assessed in
the next modules.</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Vulnerability Storage</title>
        <p>The VDM DB is a central component that stores the JSON files generated by the vulnerability
scanner module. Examples of this information include CVEs, CWEs, CVSS, vulnerability
descriptions, attack patterns, related assets, and relevant information associated to the detected
vulnerabilities from all assets composing the target system. The VDM DB is the connection
entity among all VDM components (i.e., Vulnerability scanner, assessment, reporting &amp; sharing).
The VDM DB allows the retrieval of vulnerabilities and risk information related to assets
composing the target infrastructure.</p>
      </sec>
      <sec id="sec-3-3">
        <title>3.3. Vulnerability Assessment</title>
        <p>This module analyzes the list of detected vulnerabilities, classifies them according to their
category, assigns them priorities based on their risk levels and provides treatment to avoid/mitigate
them. Details on the Vulnerability Assessment process is provided in Section 4. Based on
the obtained score, the risk associated to a given vulnerability can be classified as: (i)
Critical,   &gt;= 4.1
1.1 &gt;=   &lt;= 2.0
; (ii) High, 3.1 &gt;=   &lt;= 4.0
; (iii) Medium, 2.1 &gt;=   &lt;= 3.0
; (iv) Low,
and (v) Negligible, 0.0 &gt;=   &lt;= 1.0
.</p>
      </sec>
      <sec id="sec-3-4">
        <title>3.4. Reporting and Intelligence Sharing</title>
        <p>The VDM tool produces a vulnerability report with valuable information about the target
network/hosts and their associated vulnerabilities. The report is stored in the VDM DB and can be
displayed in a dashboard or exported in PDF, or STIX1 format. This latter uses STIX objects (e.g.,
event objects) that can also be integrated in the VDM DB. An Event object describes a dynamic
observable cyber event (e.g., the occurrence of an attack). Healthcare organizations have the
possibility to share their vulnerability results and new discoveries with other organizations,
communities and research groups using the Malware Information Sharing Platform (MISP2) as
the reporting and intelligence sharing platform.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Multi-factor Assessment Mechanism</title>
      <p>The Vulnerability Assessment (  ) value is a metric that comprises three main parameters: (i)
Root cause, (ii) Impact, and (iii) Remediation, as shown in Equation 1.</p>
      <p>=

_ +   + 

(1)</p>
      <p>Please note that “n” corresponds to the number of parameters composing the equation from
which the value is diferent from null. If information is not available in any of the parameter, it
will be discarded from the analysis. The remainder of this section details the identification of
each of the parameters composing Equation 1 .</p>
      <sec id="sec-4-1">
        <title>4.1. Root Cause</title>
        <p>It identifies the main root causes of security vulnerabilities. The cause can be known or unknown.
Known causes can be further classified as complexity, open connections, weak passwords, design
lfaws, and human factor (as shown in Table 1) [15, 16].</p>
        <p>Root Cause Description
Human Vulnerabilities caused due to insuficient training, unawareness, and lack
Factor of experience, causing coding errors and improper management of assets
and data.</p>
        <p>Design Flaws Design flaws and bugs in software and hardware. Example: Bugs in widely
used operating systems and browsers can expose millions of businesses to
significant risks.</p>
        <p>Failures Ordinary malfunctions and hardware/software failures due to technical
issues that could lead to a denial of service of the system.</p>
        <p>Complexity Security vulnerabilities rise proportionally with complexity. Complex
software, hardware, information, businesses and processes can all introduce
security vulnerabilities.</p>
        <p>Weak Pass- Passwords are used to secure virtually everything: mobile devices, software,
words websites, company VPNs and enterprise software. Despite education about
the dangers — many people still write passwords down, share them or give
them out to websites.</p>
        <p>Open Connec- Each open connection is a potential avenue for exploitation. Examples:
tions wired internet, mobile devices, WiFi, open ports, etc.</p>
        <p>Unknown No information is available to assess this parameter.</p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. Vulnerability Impact</title>
        <p>It assesses the potential impact of a given vulnerability if successfully exploited on the target
system/network. It considers three main aspects: (i) data at risk, (ii) severity, and (iii) damage.
4.2.1. Data at risk:
4.2.2. Severity:
It identifies and assesses the type of information that needs protection in the organization e.g.,
Personally Identifiable Information (PII), Intellectual Property Data (IPD), Financial Data, Social
Media, etc. (as shown in Table 2) [17, 18].</p>
        <p>It considers the CVSS base metric group that represents intrinsic characteristics and severity
of a vulnerability that are constant over time and across user environments. It is composed of
exploitability metrics (e.g., attack vector, attack complexity, privileges required, user interaction);
and impact metrics (i.e., confidentiality, integrity, availability).</p>
        <p>Based on the CVSS results, vulnerabilities are assigned a severity score as follows: None:
no severity with CVSS = 0.0 (severity = 1), Low: 0.1 &gt;=   &lt;= 3.9 (Severity =2), Medium:
4.2.3. Damage:
(Severity=3), High: 7.0 &gt;=   &lt;= 8.9
(Severity = 4), and Critical:
Data at Risk
PII
Financial
Data
IPD
Social media
accounts
Third-party
data
Social
work data
Data that could potentially identify a specific individual, e.g., medical
information, birth date, social security numbers, citizen ID, etc.</p>
        <p>Related to the ofering or delivery of a financial product/service or
processing of a purchase (e.g., credit card, bank account, loan, etc.).</p>
        <p>It refers to sales and marketing plans, new product plans, patents, customer
It refers to information often used for authenticating to various applications</p>
        <p>It refers to any kind of data accessed, handled and/or supplied by third
net- It refers to data about the vulnerable organization/product that is publicly
available in social networks, blogs and public websites.</p>
        <p>No information is available to assess this parameter.</p>
        <p>Score
5
5
5
4
3
2
It considers the potential damage that could be caused by a breach of the afected system if the
vulnerability is successfully exploited (as seen in Table 3).</p>
        <p>Damage
Total Damage
Partial Damage</p>
        <p>The system is expected to be partially damaged due to the
NO/Low Damage</p>
        <p>The system is not expected to be damaged due to the successful
Description
The system is expected to be highly damaged due to the
successful exploitation of the vulnerability.</p>
        <p>successful exploitation of the vulnerability.</p>
        <p>The vulnerability impact is a metric composed of three parameters: (i) the data at risk, (ii)
the severity, and (iii) the damage (as shown in Equation 2).</p>
        <p>=

_ _ +   
+ 

(2)</p>
        <p>Please note that “n” corresponds to the number of parameters composing the equation from
which the values are diferent from null. If information is not available in any of the parameter</p>
      </sec>
      <sec id="sec-4-3">
        <title>4.3. Remediation</title>
        <p>It assesses the potential capabilities for an organization to implement and recover for a successful
exploitation of a given vulnerability in its system. It considers the recovery time, requirements,
resilience, costs and recovery level.</p>
        <sec id="sec-4-3-1">
          <title>4.3.1. Recovery Time:</title>
          <p>It identifies and assesses the time needed for an infrastructure to recover from a given attack,
assuming the vulnerability is successfully exploited by a malicious entity (as seen in Table 4).</p>
          <p>Recovery Time
Long
It identifies and assesses the type of security measures (e.g., protective, reactive) the target
system needs to implement in order to recover from a given attack (as seen in Table 5).</p>
          <p>Requirements
New measures
Existing measures
No measure
Unknown</p>
          <p>Description
The system requires implementing new reactive or protective
measures).</p>
          <p>The system requires implementing existing measures.</p>
          <p>The system does not require to implement any measure.</p>
          <p>No information is available to assess this parameter.
It identifies and assesses the actions needed by the target system to keep running after a
vulnerability has been detected and/or exploited (as seen in Table 7).
The system requires to remove the vulnerability to keep running.</p>
          <p>The system does not require to remove the vulnerability, but its removal is
highly recommended to keep running.</p>
          <p>No need to remove the vulnerability to keep running.</p>
          <p>No information is available to assess this parameter.</p>
          <p>It identifies and assesses level of recovery expected for the target system after the implementation
of security measures (as seen in Table 8).</p>
          <p>Score
Score
5
3
Score
5
3
1</p>
        </sec>
        <sec id="sec-4-3-2">
          <title>4.3.5. Recovery Level:</title>
          <p>resilience, cost and recovery level parameters, as shown in Equation 3.</p>
          <p>=
  
_  +   +  +  +   

_ 
(3)</p>
          <p>Please note that “n” corresponds to the number of parameters composing the equation from
which the value is diferent from null. If information is not available in any of the parameter</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Example of Usage</title>
      <p>Considering a vulnerability of a remote code execution detected in a server from a healthcare
organization (as shown in Annex A), the first step on the vulnerability assessment process is to
identify the root cause. Although this is not clearly specified in the provided information, a
remote code execution can be associated to multiple causes (e.g., open connections, weak
passwords, complexity, design flaws, human factors, or a combination of some of them), therefore,
the  _ score is set to five (5).</p>
      <p>The second step is to compute the vulnerability impact. Considering that the vulnerability is
associated to a hospital server, the remote code execution could lead to the identification of
personal data (e.g., medical information), therefore the  _ _  score is set to five (5). In
addition, the CVSS value for this vulnerability is equivalent to ten (10), therefore, the   
score is set to five (5), and since the system is expected to be partially damaged due to the
successful exploitation of the vulnerability, its  score is set to three (3). As a result, the
  value for this vulnerability is 4.33.</p>
      <p>The third step is to compute the vulnerability remediation value. For that, the following
assumptions have been made:
• The system can be easily recovered in a short period of time (   _  = 1)
• The system requires implementing new security measures (  = 5)
• The system does not need to remove the vulnerability to keep running ( = 1)
• No information is available to assess the cost parameter ( = 0). This parameter is
therefore not considered in the score calculation.
• After the implementation of a mitigation measure, the system is expected to be fully
operative (   _  =1)
Therefore, the  score is equivalent to 2.</p>
      <p>The final step consists on calculating the Vulnerability Assessment (VA) and classification.
As a result,   = 3.78 , which corresponds to a HIGH priority.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Related Work</title>
      <p>Novel approaches and tools based on old and recent technologies aim to filling possible security
gaps underlying in modern healthcare cyber solutions. However, while it is important to
safeguard the digital infrastructures from those who threaten them, it is also important to do
so without disrupting the continuous healthcare procedures, or making them too complex to
use for people with no technical background, such as the patients and the medical staf. To
protect healthcare organizations, a cybersecurity solution needs to be in position to monitor and
control all the security-critical aspects. Several solutions to identify and detect vulnerabilities
in healthcare infrastructures have been proposed so far, nonetheless, few of them perform a
thorough approach to assess and classify their severity.</p>
      <p>The Cybersecurity and Infrastructure Security Agency (CISA3) has initiated an efort to
enhance security, resiliency and reliability of the Nation’s cybersecurity and communication
infrastructure. The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT4)
is a CISA initiative that provides a control system security focus in collaboration with US-CERT
to conduct vulnerability and malware analysis, share and coordinate vulnerability information
and threat analysis through information products and alerts, among other services.</p>
      <p>Commercial solutions (e.g., Bugcrowd’s crowdsourced security [19]) are available in the
market to help healthcare organizations to discover and manage critical vulnerabilities in
the health sector. The solution enables healthcare professionals to assess the risk associated
with disparate data sources and infrastructure and ensures compliance with the General Data
Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act
(HIPAA). Other well-known commercial and open-source solutions (e.g., Nessus5, OpenVAS6)
provide vulnerability assessment capabilities that strongly depend on the CVSS results.</p>
      <p>A vulnerability database containing timely information about current security issues,
weaknesses, vulnerabilities and exploits on industrial control systems is publicly available as part of
the CISA services and frequently updated by ICS-CERT advisories. Similar to the CVE database,
the ICS-CERT Advisories database provides a list of industrial control system vulnerabilities.
However, several issues have been recently identified [ 20]: (i) The provided recommendations
are generic and, in some cases, meaningless; (ii) Industrial impact is ignored; (iii) Likelihood of
exposure is missing; (iv) Some advisories contain errors in the CVE and CVSS score; (v) It may
take months or years to get to a resolution; and (vi) Some vulnerabilities may not be mitigable
besides patching, and some of them provide no advice at all.</p>
      <p>In order to cope with the aforementioned shortcomings, we propose a vulnerability discovery
manager that uses a multi-factor assessment mechanism to define priorities on vulnerabilities
afecting critical infrastructures with a particular focus on healthcare organizations.</p>
    </sec>
    <sec id="sec-7">
      <title>7. Conclusions</title>
      <p>This paper presents a multi-factor assessment mechanism to classify define priorities of
vulnerabilities afecting Healthcare infrastructures. It details a tool named Vulnerability Discovery
Manager (VDM) which is composed of four main modules: (i) a vulnerability scanner, to check
for vulnerabilities of the target nodes; (ii) a vulnerability storage, to save discovered
vulnerabilities in a local database; (iii) a vulnerability assessment, to prioritize vulnerabilities and provide
mitigation guidance; and (iv) a report and intelligence sharing, to communicate and share VDM
output with other healthcare institutions.</p>
      <p>The proposed assessment mechanism considers not only the vulnerability root causes, but
also its impact and potential remediation actions to be implemented. As a result, a score ranging
form zero to five is assigned to a particular vulnerability and shared in a platform where other
healthcare centers and research organizations can benefit.</p>
      <p>An example of usage is provided in Section 5 to show the applicability of our proposed
mechanism over a vulnerability report generated by the VDM in a JSON format. Future work will
focus on evaluating other factors and refining current values used to compute the vulnerability
4https://us-cert.cisa.gov/ics
5https://www.tenable.com/products/nessus
6https://www.openvas.org/
assessment score.</p>
    </sec>
    <sec id="sec-8">
      <title>Acknowledgments</title>
      <p>The research work presented in this article has been supported by the European Commission
under the H2020 Programme, through funding of the “CUREX: seCUre and pRivate hEalth data
eXchange” project (G.A. id: 826404).
[13] Health Tech Staf, Ho healthcare can pinpoint common vulnerabilities – and
build defenses, [online], 2018. https://healthtechmagazine.net/article/2018/07/
how-healthcare-can-pinpoint-common-vulnerabilities-and-build-defenses.
[14] Ponemon Institute, Medical device security: An industry under attack and unprepared
to defend, [online], 2017. https://www.synopsys.com/content/dam/synopsys/sig-assets/
reports/medical-device-security-ponemon-synopsys.pdf.
[15] John Spacey, The 10 root causes of security vulnerabilities, [online], 2013. https://arch.</p>
      <p>simplicable.com/arch/new/10-root-causes-of-security-vulnerabilites.
[16] A. V. Revnivykh, A. Fedotov, Root causes of information systems vulnerabilities 8 (2015).
[17] European for Information Technology, 3 types of data that need protection, [online], last
visited February 2021. https://europeanitc.com/the-quick-brown-fox/.
[18] Joseph Streinberg, 12 types of data that businesses need to
protect but often do not, [online], 2018. https://josephsteinberg.com/
12-types-of-data-that-businesses-need-to-protect-but-often-do-not/.
[19] Bugcrowd, Why healthcare it should include crowdsourced security, [online], 2019. https:
//www.bugcrowd.com/blog/why-healthcare-it-should-include-crowdsourced-security/.
[20] Dragos, Industrial controls system vulnerabilities, [online], 2018. https://dragos.com/
wp-content/uploads/yir-ics-vulnerabilities-2018.pdf.</p>
      <p>A. Extract from a VDM report in JSON format
{</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>F.</given-names>
            <surname>Donovan</surname>
          </string-name>
          , Reports of healthcare it infrastructure vulnerabilities surge 341%, [online],
          <year>2019</year>
          . https://hitinfrastructure.com/news/ reports
          <article-title>-of-healthcare-it-infrastructure-vulnerabilities-surge-341.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>Ayala</given-names>
            <surname>Goldstein</surname>
          </string-name>
          ,
          <article-title>The future of vulnerability management programs</article-title>
          ,
          <source>[online]</source>
          ,
          <year>2018</year>
          . https://resources.whitesourcesoftware.
          <article-title>com/blog-whitesource/ the-future-of-vulnerability-management-programs.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>Ayala</given-names>
            <surname>Goldstein</surname>
          </string-name>
          ,
          <article-title>Vulnerability management - what you need to know</article-title>
          , [online],
          <year>2020</year>
          . https://resources.whitesourcesoftware.com/blog-whitesource/vulnerability-management.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <article-title>[4] FIRST, Common vulnerability scoring system v3.1: Specification document</article-title>
          , [online],
          <source>last visited February</source>
          <year>2021</year>
          . https://www.first.org/cvss/v3.1/specification-document.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <article-title>[5] NOPSEC, State of vulnerability risk management report</article-title>
          , [online],
          <year>2018</year>
          . http://info.nopsec. com/rs/736-UGK-525/images/NopSec_2018
          <source>_SOV_Report.pdf.</source>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Bugcrowd</surname>
          </string-name>
          , State of healthcare security in
          <year>2019</year>
          , [online],
          <year>2019</year>
          . https://www.bugcrowd. com/blog/state-of-healthcare-security/.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Y.</given-names>
            ,
            <surname>Nikoloudakis</surname>
          </string-name>
          ; and
          <string-name>
            <given-names>E.</given-names>
            ,
            <surname>Pallis</surname>
          </string-name>
          ; and
          <string-name>
            <surname>G.</surname>
          </string-name>
          , Mastorakis; and
          <string-name>
            <given-names>C. X.</given-names>
            ,
            <surname>Mavromoustakis</surname>
          </string-name>
          ; and
          <string-name>
            <given-names>C.</given-names>
            ,
            <surname>Skianis</surname>
          </string-name>
          ; and
          <string-name>
            <given-names>E. K.</given-names>
            ,
            <surname>Markakis</surname>
          </string-name>
          ,
          <article-title>Vulnerability assessment as a service for fog-centric ict ecosystems: A healthcare use case 12 (</article-title>
          <year>2019</year>
          )
          <fpage>1216</fpage>
          -
          <lpage>1224</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>S.</surname>
          </string-name>
          , Safavi; and
          <string-name>
            <given-names>A. M.</given-names>
            ,
            <surname>Meer</surname>
          </string-name>
          ; and
          <string-name>
            <surname>E. K. J.</surname>
          </string-name>
          , Melanie; and
          <string-name>
            <given-names>Z.</given-names>
            ,
            <surname>Shukur</surname>
          </string-name>
          (Ed.),
          <source>Cyber Vulnerabilities on Smart Healthcare, Review and Solutions, IEEE Cyber Resilience Conference (CRC)</source>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Strielkina</surname>
          </string-name>
          ; and
          <string-name>
            <given-names>V.</given-names>
            ,
            <surname>Kharchenko</surname>
          </string-name>
          ; and
          <string-name>
            <given-names>D.</given-names>
            ,
            <surname>Uzun</surname>
          </string-name>
          (Ed.),
          <article-title>Availability models for healthcare IoT systems: Classification and research considering attacks on vulnerabilities</article-title>
          ,
          <source>IEEE 9th International Conference on Dependable Systems, Services and Technologies (DESSERT)</source>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>D. I.</surname>
          </string-name>
          , Dogaru; and
          <string-name>
            <given-names>I.</given-names>
            ,
            <surname>Dumitrache</surname>
          </string-name>
          (Ed.),
          <article-title>Cyber security in healthcare networks</article-title>
          ,
          <source>IEEE E-Health and Bioengineering Conference (EHB)</source>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>D.</surname>
          </string-name>
          , Kotz; and
          <string-name>
            <given-names>K.</given-names>
            ,
            <surname>Fu</surname>
          </string-name>
          ; and
          <string-name>
            <given-names>C.</given-names>
            ,
            <surname>Gunter</surname>
          </string-name>
          ; and
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Rubin</surname>
          </string-name>
          ,
          <article-title>Security for mobile and cloud frontiers in healthcare 58 (</article-title>
          <year>2015</year>
          )
          <fpage>21</fpage>
          -
          <lpage>23</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Stoyanova</surname>
          </string-name>
          ; and
          <string-name>
            <given-names>Y.</given-names>
            ,
            <surname>Nikoloudakis</surname>
          </string-name>
          ; and
          <string-name>
            <surname>S.</surname>
          </string-name>
          , Panagiotakis; and
          <string-name>
            <given-names>E.</given-names>
            ,
            <surname>Pallis</surname>
          </string-name>
          ; and
          <string-name>
            <given-names>E. K.</given-names>
            <surname>Markakis</surname>
          </string-name>
          (Ed.),
          <article-title>A Survey on the Internet of Things (IoT) Forensics: Challenges, Approaches</article-title>
          and Open Issues,
          <source>IEEE Communications Surveys &amp; Tutorials</source>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>